Privacy Policy
Last updated: September 11, 2026
1. Scope and responsible party
This Policy explains how Bulest collects, accesses, uses, stores, shares and deletes information when you use our platform, including its channels, automated agents, integrations and Payment Verifier. For privacy questions or requests, contact info@bulest.co.
2. Information we process
- Account and profile: name, email address, phone number, organization, plan, collaborators and preferences.
- Business operations: channels, conversations, customers, agents, stores, orders, verifications and action history.
- Integrations: identifiers, permissions and credentials needed to maintain the services you authorize.
- Security and diagnostics: technical logs, device information, IP address, access attempts and events needed to prevent abuse and resolve failures.
3. Data obtained through Google APIs
Gmail access is optional and is activated only when you explicitly connect an account to Payment Verifier. Bulest requests read-only access to detect financial notifications; it does not modify, send or delete your emails.
During initial setup, Bulest may search for up to 50 payment notifications from the previous 30 days, using a query restricted to authorized financial senders. After setup, it processes new Inbox messages for this feature. It first screens the available minimum metadata, such as sender, subject, date and authentication information, and retrieves a message's content only when its sender matches the authorized financial-sender catalog.
For messages from authorized financial senders, we may process:
- connected account, sender, subject, date and message identifier;
- the visible content of the financial notification that is strictly necessary;
- amount, currency, reference, provider, status, payer, recipient and other transaction information present;
- derived data, such as matches, risk alerts and verification traceability.
Messages that do not match authorized financial senders are excluded from financial processing: Bulest does not retrieve their content or add them to payment records.
Permissions and user-facing purpose. https://www.googleapis.com/auth/userinfo.email identifies the connected mailbox displayed in Bulest. https://www.googleapis.com/auth/gmail.readonly lets Bulest retrieve financial-notification bodies and show extracted payment details for reconciliation. Email identity alone does not provide messages, and gmail.metadata does not provide their bodies, where amounts, payment references and transaction details are found. Bulest does not request Gmail write permissions for this feature.
4. Purpose and Google Limited Use
We use Gmail data exclusively to provide and improve the visible feature you requested: detecting financial notifications, structuring their data, displaying transactions, verifying payment receipts, preventing reuse or fraud, and preserving traceability.
- We do not sell data obtained from Google.
- We do not use it for advertising, commercial targeting, advertising profiles or credit assessments.
- We do not use it to train generalized or personalized artificial intelligence models.
- We do not transfer it except as needed to provide the requested feature, with your authorization, for security, to comply with legal obligations, or in other cases permitted by Google.
Our use and transfer to other applications of raw, aggregated, anonymized or derived data received from Google Workspace APIs will adhere to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including their Limited Use requirements. This data must not be used or transferred to create, train or improve foundational or generalized AI/ML models, including by a service provider.
5. Automated processing and providers
Bulest operates Payment Verifier on infrastructure managed by Bulest. For notifications from authorized financial senders, Bulest sends Google, through Gemini API, the content and metadata strictly necessary to extract and evaluate payment data.
The purpose of this transfer is to extract and evaluate the data needed for the merchant-requested feature. Bulest does not use or authorize the use of Gmail data for providers' independent purposes, advertising or training generalized or personalized AI models. AI integrations must comply with the Limited Use restrictions described in this Policy. Google's processing is governed by the applicable Gemini API terms.
6. Limited human access
Our personnel may not read data obtained from Gmail except where strictly necessary and permitted: with your explicit consent to resolve a specific support case; to investigate abuse or a security incident; to comply with a legal obligation; or when data has been aggregated and anonymized for a permitted internal operation. Access is restricted to authorized personnel and the minimum information necessary.
7. Security and storage
We apply technical and organizational controls, including HTTPS in transit, field-level encryption of OAuth credentials at rest, account separation, access permissions, credential revocation, change traceability and controls against unauthorized access. No system is infallible; we review our measures based on risk and the evolution of the service.
8. Retention and deletion
We retain credentials and financial notifications while the integration is active and they are needed to provide the service. When an email account is disconnected, Bulest stops synchronization, asks Google to stop monitoring and revokes credentials; it also deletes the local OAuth account and associated raw banking-email records.
Structured transaction data and security records may be retained while the Bulest account remains active to provide traceability, prevent fraud and comply with legal obligations. You may request deletion of your account and associated data by contacting info@bulest.co. Any additional retention is limited to what is required by law or necessary to establish, exercise or defend claims.
9. User control
You can manage your integrations in Bulest, disconnect Gmail at any time or revoke access in your Google Account's security settings. You can also request access to, correction of or deletion of your data through our contact channel.
10. Changes and contact
We may update this Policy to reflect legal, technical or functional changes. We will publish the current version and its update date. For questions, support or requests involving Google data, contact info@bulest.co.
